# Team8's $365 Million Raise Is Really a Story About Who's Buying


Three companies. One acquirer. A pattern worth watching.


When Israeli venture firm Team8 announced another $365 million in capital this week — $265 million for its third fund and $100 million earmarked for follow-on bets in existing portfolio companies — the headline wrote itself as another cybersecurity funding milestone. But the more interesting story is sitting right there in the portfolio section: Talon, Dig, and Koi, three Team8 incubated companies, were all acquired by Palo Alto Networks.


That's not coincidence. That's a thesis playing out in real time.


## The Palo Alto Feeder Fund Nobody Calls a Feeder Fund


Team8 operates on a venture-creation model — a structure that's meaningfully different from traditional VC. Rather than writing checks into founders who already have a plan, Team8 co-founds companies, which means it's embedding itself at the idea stage, helping recruit the team, shaping the product, and then funding what it helped build.


The result, at least in cybersecurity, has been a remarkably consistent exit pattern. Talon (enterprise browser security) was acquired by Palo Alto Networks in late 2023. Dig Security (cloud data security posture management) was snapped up around the same period. Koi followed. Three portfolio companies in succession landing at the same buyer isn't just good luck — it suggests Team8's incubation model is producing the exact category of enterprise security product that Palo Alto Networks' platform strategy requires.


This matters for anyone trying to read where enterprise security is heading. Palo Alto's platformization bet — consolidating point solutions into a single integrated stack — has been the defining narrative in enterprise security for three years. Team8 appears to be building companies specifically shaped to slot into that kind of architecture: well-defined, filling a real gap, ready for integration. Whether that's deliberate alignment or just good product instincts matching the market doesn't change the practical outcome.


## $2 Billion AUM, and the Clock Is Now on AI


Since 2014, Team8 has accumulated close to $2 billion in assets under management. For context, that's a firm that has spent twelve years developing deep relationships in Israeli intelligence and military technology communities — Unit 8200 veterans are a consistent throughline in Team8's founding network — and channeling that talent pipeline toward enterprise security problems.


The current portfolio class tells you exactly where they've moved their chips. This year's investments include Frame Security, Act Security, Mate Security, Jazz, Fig Security, Astelia, and Lema AI. The names alone reveal the gravitational center: identity, access, and AI-native tooling. "Act," "Frame," "Mate," and "Fig" all sound like security products built around agentic workflows or AI interaction layers — the kinds of surfaces that didn't exist meaningfully at enterprise scale three years ago and are now where every serious attacker is probing.


Sarit Firon, Team8's managing partner, was careful about how she framed the firm's AI thesis: "Competitive advantage won't come from the model underneath a product — it will come from solving fundamental enterprise problems that stay relevant across technology cycles." That's a deliberate hedge. Team8 isn't betting on a specific foundation model winning. They're betting that the enterprise problems AI creates — new attack surfaces, new identity flows, new data exposure patterns — are durable regardless of which model sits underneath.


That's actually a smarter bet than most of what you hear on conference stages right now.


## What the Enterprise Security Market Looks Like From Here


The $365 million raise lands during a peculiar moment. Black Hat 2026 is underway, which means the market is flooded with announcements — several other firms raised this week alone, including Mindgard ($30M for AI system protection) and Corma ($60M for defensive AI models). The signal-to-noise ratio in security funding right now is genuinely poor.


But Team8's raise is structurally distinct from most of what's hitting the wire. The $100 million follow-on tranche — capital specifically reserved for doubling down on existing portfolio companies — suggests Team8 has already seen enough internal evidence to identify which bets are working. In a market where many early-stage AI security companies are still pre-revenue or pre-product, that internal intelligence advantage is real.


The question defenders should be asking isn't "should I pay attention to this funding round" — it's "which of these seven new portfolio companies is going to matter in 18 months, and am I ahead of whatever problem they're solving?"


---


## HackWire Analysis


The Team8 raise is notable less for the dollar figure than for what it reveals about the structural dynamics of enterprise security investment.


Three consecutive Palo Alto Networks acquisitions from a single incubator isn't a coincidence — it's evidence of a deliberate co-development pipeline, even if it's never described that way publicly. This creates an interesting competitive dynamic: if you're building enterprise security products and your potential acquirers are essentially co-investing in your competitors' early stages through firms like Team8, you're operating on an uneven playing field before you've shipped a product.


The pivot to AI-native tooling is also worth reading carefully. Team8's portfolio companies this cycle are almost entirely oriented around the problems AI *creates* for enterprises rather than AI as a defensive tool. Frame Security, Act Security, the various "Mat/Fig/Jazz" plays — these are products built for a world where enterprise environments include AI agents, LLM-accessible data stores, and non-human identities executing autonomous workflows. That threat surface barely existed at scale in 2023. It's now mainstream.


What's missing from most coverage of this raise is the recruiting dimension. Team8's "Village" model — the network of enterprise security executives it cultivates as advisors, pilot customers, and eventual acquirers — is the real moat. Capital alone doesn't produce three acquisitions by the same buyer. Deep integration into the CIO/CISO decision-making layer does. The $365 million buys runway; the Village buys distribution.


For defenders, the practical read is this: pay attention to what Team8's portfolio is solving for. If their last cycle predicted the Palo Alto platform priorities three years in advance, their current bets on AI-native identity and agentic security tooling are telling you something about where your enterprise attack surface is headed before your adversaries have fully mapped it themselves.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)